¡¾Îó²îͨ¸æ¡¿Cisco ASA & FTD¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2024-20481£©
Ðû²¼Ê±¼ä 2024-10-25Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Cisco ASA & FTD¾Ü¾øÐ§ÀÍÎó²î | ||
CVE ID | CVE-2024-20481 | ||
Îó²îÀàÐÍ | Dos | ·¢Ã÷ʱ¼ä | 2024-10-25 |
Îó²îÆÀ·Ö | 5.8 | Îó²îÆ·¼¶ | ÖÐΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ÒÑ·¢Ã÷ |
Cisco Adaptive Security Appliance£¨ASA£© ÊÇÒ»¿îÓÉ˼¿Æ¹«Ë¾£¨Cisco£©¿ª·¢µÄÍøÂçÇå¾²×°±¸£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÌṩ·À»ðǽ¡¢ÐéÄâרÓÃÍøÂ磨VPN£©ºÍÈëÇÖ·ÀÓùµÈÇå¾²¹¦Ð§£¬£¬£¬£¬£¬£¬£¬£¬ASA ×°±¸±»ÆÕ±éÓ¦ÓÃÓÚÆóÒµºÍ×éÖ¯µÄÍøÂçÇå¾²¼Ü¹¹ÖУ¬£¬£¬£¬£¬£¬£¬£¬Äܹ»ÓÐÓñ£»£»£»£»¤ÄÚ²¿ÍøÂçÃâÊÜÍⲿÍþв¡£¡£¡£¡£¡£¡£¡£Cisco Firepower Threat Defense£¨FTD£©ÊÇCiscoÍÆ³öµÄÒ»¿î¼¯³É»¯ÍøÂçÇå¾²½â¾ö¼Æ»®£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÌṩÖÜÈ«µÄÍøÂç±£»£»£»£»¤¡£¡£¡£¡£¡£¡£¡£
2024Äê10ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¿·¢k8¼¯ÍÅVSRC¼à²âµ½CiscoÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËCisco ASA ºÍFTDÖеÄÒ»¸ö¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2024-20481£©£¬£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ5.8£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ¸ÃÎó²îÒÑ·¢Ã÷±»Ê¹Óᣡ£¡£¡£¡£¡£¡£
¸ÃÎó²î±£´æÓÚCisco ASA ºÍFTDÈí¼þµÄÔ¶³Ì»á¼ûVPN (RAVPN) ЧÀÍÖУ¬£¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄ×°±¸·¢ËÍ´ó×ÚVPN Éí·ÝÑéÖ¤ÇëÇóÀ´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÄ¿µÄ×°±¸×ÊÔ´ºÄ¾¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂRAVPNЧÀ;ܾøÐ§ÀÍ(DoS)¡£¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
ÈôÊÇ˼¿Æ²úÆ·ÔËÐеÄÊDZ£´æÎó²îµÄ Cisco ASA »ò FTD Èí¼þ°æ±¾²¢ÆôÓÃÁË RAVPN ЧÀÍ£¬£¬£¬£¬£¬£¬£¬£¬ÔòÒ×ÊܸÃÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£¡£
1.Ϊ×ÊÖú¿Í»§È·¶¨Æä Cisco ASA¡¢FMC ºÍ FTD Èí¼þÖÐÊÇ·ñ±£´æÎó²î£¬£¬£¬£¬£¬£¬£¬£¬Ë¼¿ÆÌṩÁË˼¿ÆÈí¼þ¼ì²éÆ÷¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉʹÓøù¤¾ßÅжÏÄ¿½ñ×°±¸µÄÈí¼þ°æ±¾ÊÇ·ñÊÜÕâЩÎó²îÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬²¢¸üе½²»ÊÜÓ°Ïì°æ±¾¡£¡£¡£¡£¡£¡£¡£ÒªÊ¹Óøù¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬ÇëתÖÁCisco Software CheckerÒ³Ãæ²¢Æ¾Ìý˵Ã÷¾ÙÐвÙ×÷£ºhttps://sec.cloudapps.cisco.com/security/center/softwarechecker.x
2. È·¶¨SSL VPN ÉèÖᣡ£¡£¡£¡£¡£¡£Ö»ÓÐÆôÓÃRAVPNЧÀͲŻªÊ¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÒªÈ·¶¨ÊÇ·ñÆôÓÃÁËSSL VPN£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚ×°±¸CLIÉÏʹÓÃshow running config webvpn|include^enableÏÂÁî¡£¡£¡£¡£¡£¡£¡£ÒÔÏÂʾÀýÏÔʾÁËÔÚÍⲿ½Ó¿ÚÉÏÆôÓÃÁËSSL VPNµÄ×°±¸ÉÏÔËÐÐshow running-config webvpn | include ^ enableÏÂÁîµÄÊä³ö£º
firewall# show running-config webvpn | include ^ enable
enable outside
ÈôÊǸÃÏÂÁîûÓÐÊä³ö£¬£¬£¬£¬£¬£¬£¬£¬ÔòÌåÏÖÈκνӿÚÉ϶¼Î´ÆôÓà SSL VPN£¬£¬£¬£¬£¬£¬£¬£¬ÇÒ×°±¸²»Ò×Êܵ½¸ÃÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£¡£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ¸ÃÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉʹÓùٷ½ÌṩµÄ¹¤¾ß»ò²½·¥¾ÙÐÐÅŲ飬£¬£¬£¬£¬£¬£¬£¬²¢Éý¼¶µ½²»ÊÜÓ°Ïì/×îÐÂÐÞ¸´°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬»ò¹Ø±Õ×°±¸Ò×Êܹ¥»÷µÄÉèÖú͹¦Ð§ÒÔ»º½â¸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-bf-dos-vDZhLqrW
3.2 ÔÝʱ²½·¥
¹ØÓÚÊܵ½ÃÜÂëÅçÈ÷¹¥»÷ÇÒÉÐδÉý¼¶µ½ÐÞ¸´°æ±¾µÄÓû§£¬£¬£¬£¬£¬£¬£¬£¬¿É²Î¿¼ÒÔÏÂÁ´½ÓÓ¦Óûº½â²½·¥£º
https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-bf-dos-vDZhLqrW
https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-10-25 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¿·¢k8¼ò½é
¿·¢k8½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¿·¢k8´óÏ㬣¬£¬£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬£¬¿·¢k8ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£¡£
5.2 ¹ØÓÚ¿·¢k8
¿·¢k8Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ